Section: .. / 0710-advisories /
| /// File Name: |
sa27321.txt |
Description:
|
Secunia Security Advisory - Multiple vulnerabilities have been reported in IBM Lotus Domino, which can be exploited by malicious, local users to gain knowledge of sensitive information and by malicious users to bypass certain security restrictions or compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/27321/ | | File Size: | 3314 | | Last Modified: | Oct 23 20:05:15 2007 |
| MD5 Checksum: | da1e2e64ee10e553b312eaa352c1239e |
|
| /// File Name: |
ZDI-07-058.txt |
Description:
|
This vulnerability allows remote attackers to inject arbitrary SQL on vulnerable installations of Oracle E-Business Suite. Authentication is not required to exploit this vulnerability. E-Business Suite 11 and 12 are affected.
| | Author: | Joxean Koret | | Homepage: | http://www.zerodayinitiative.com/ | | File Size: | 3304 | | Related CVE(s): | CVE-2007-5766 | | Last Modified: | Oct 31 20:07:11 2007 |
| MD5 Checksum: | 6a128b61e3baa27426a685bf715462aa |
|
| /// File Name: |
SA-20071012-0.txt |
Description:
|
SEC Consult Security Advisory 20071012-0 - A specially crafted beacon frame can cause MadWifi to crash and cause a kernel panic on the affected machine. Versions 0.9.3.2 and below are affected.
| | Author: | Clemens Kolbitsch, Sylvester Keil | | Homepage: | http://www.sec-consult.com/ | | File Size: | 3301 | | Last Modified: | Oct 12 21:23:11 2007 |
| MD5 Checksum: | d8cf9f006575b134a7db27aa0b2a3fd6 |
|
| /// File Name: |
sa27218.txt |
Description:
|
Secunia Security Advisory - Fedora has issued an update for wesnoth. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/27218/ | | File Size: | 3299 | | Last Modified: | Oct 12 21:32:59 2007 |
| MD5 Checksum: | 83234ed2f8d98766ab819926fd1a05b1 |
|
| /// File Name: |
glsa-200710-03.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200710-03 - David Thiel of iSEC Partners discovered a heap-based buffer overflow in the _01inverse() function in res0.c and a boundary checking error in the vorbis_info_clear() function in info.c. libvorbis is also prone to several Denial of Service vulnerabilities in form of infinite loops and invalid memory access with unknown impact. Versions less than 1.2.0 are affected.
| | Homepage: | http://security.gentoo.org/ | | File Size: | 3294 | | Related CVE(s): | CVE-2007-3106, CVE-2007-4029, CVE-2007-4065, CVE-2007-4066 | | Last Modified: | Oct 8 20:37:38 2007 |
| MD5 Checksum: | c70453c2482e2f78df068f65c8aead52 |
|
| /// File Name: |
glsa-200710-06.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200710-06 - Moritz Jodeit reported an off-by-one error in the SSL_get_shared_ciphers() function, resulting from an incomplete fix of CVE-2006-3738. A flaw has also been reported in the BN_from_montgomery() function in crypto/bn/bn_mont.c when performing Montgomery multiplication. Versions less than 0.9.8e-r3 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 3292 | | Related CVE(s): | CVE-2006-3738, CVE-2007-3108, CVE-2007-5135 | | Last Modified: | Oct 8 20:39:04 2007 |
| MD5 Checksum: | fbb80f53be6d2a67bf086e6f20059611 |
|
| /// File Name: |
NISR17102007D.txt |
Description:
|
NGSSoftware Insight Security Research Advisory - The Oracle RDBMS on receiving an invalid TNS data packet will use 100% of the CPU's time introducing a denial of service condition.
| | Author: | David Litchfield | | Homepage: | http://www.ngssoftware.com/ | | File Size: | 3280 | | Last Modified: | Oct 18 18:20:52 2007 |
| MD5 Checksum: | a370f981cb7f34a8094c806a8b0dfddf |
|
| /// File Name: |
sa27214.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in Cisco products, which can be exploited by malicious users to bypass certain security restrictions, disclose certain sensitive information, and manipulate certain data.
| | Homepage: | http://secunia.com/advisories/27214/ | | File Size: | 3265 | | Last Modified: | Oct 19 11:32:30 2007 |
| MD5 Checksum: | 03fce3a72d6334493bbe00dbb38fba45 |
|
| /// File Name: |
mirandaim-overflows.txt |
Description:
|
Multiple buffer overflow vulnerabilities exist in Miranda IM, a popular open source instant messaging client. Versions 0.6.8 and 0.7.0 are vulnerable.
| | Author: | David Wharton | | Homepage: | http://secureworks.com/ | | File Size: | 3261 | | Related CVE(s): | CVE-2007-5542, CVE-2007-5543 | | Last Modified: | Oct 23 19:25:20 2007 |
| MD5 Checksum: | c17ee18def8641a947376f499d6789ba |
|
| /// File Name: |
fsd-overflow.txt |
Description:
|
FSD versions 2.052 d9 and below and 3.000 d9 and below suffer from multiple buffer overflow vulnerabilities.
| | Author: | Luigi Auriemma | | Homepage: | http://aluigi.org/ | | File Size: | 3255 | | Last Modified: | Oct 2 00:33:41 2007 |
| MD5 Checksum: | fe31d80021be2ff5458d4b26d6dc1ddb |
|
| /// File Name: |
sa27298.txt |
Description:
|
Secunia Security Advisory - SUSE has issued an update for Mozilla Firefox. This fixes some vulnerabilities and weaknesses, which can be exploited by malicious people to disclose sensitive information, conduct phishing attacks, manipulate certain data, and potentially compromise a user's system.
| | Homepage: | http://secunia.com/advisories/27298/ | | File Size: | 3255 | | Last Modified: | Oct 22 22:42:45 2007 |
| MD5 Checksum: | 9e82abe113b614b0c93ffda5998c0c2d |
|
| /// File Name: |
sa27292.txt |
Description:
|
Secunia Security Advisory - Some vulnerabilities have been reported in Drupal, which can be exploited by malicious people to conduct cross-site scripting attacks and bypass certain security restrictions, and by malicious users to conduct HTTP response splitting attacks.
| | Homepage: | http://secunia.com/advisories/27292/ | | File Size: | 3240 | | Last Modified: | Oct 18 17:54:12 2007 |
| MD5 Checksum: | 3a1b6fc5490e5cf94c3a9ec901d8dbea |
|
| /// File Name: |
sa27090.txt |
Description:
|
Secunia Security Advisory - Fedora has issued an update for kdelibs. This fixes some vulnerabilities, which can be exploited by malicious people to conduct spoofing attacks.
| | Homepage: | http://secunia.com/advisories/27090/ | | File Size: | 3233 | | Last Modified: | Oct 10 00:59:53 2007 |
| MD5 Checksum: | ce30ba22cb0d508a772f78259538a363 |
|
| /// File Name: |
sa27183.txt |
Description:
|
Secunia Security Advisory - Sun has acknowledged a vulnerability in Sun Solaris, which can be exploited by malicious, local users and malicious users to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/27183/ | | File Size: | 3219 | | Last Modified: | Oct 15 16:43:14 2007 |
| MD5 Checksum: | f0efed73d3f0948ed8eb547fe765b045 |
|
| /// File Name: |
sa27220.txt |
Description:
|
Secunia Security Advisory - mu-b has reported multiple vulnerabilities in eXtremail, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/27220/ | | File Size: | 3209 | | Last Modified: | Oct 16 18:55:49 2007 |
| MD5 Checksum: | 8dc3af5de36e5e4163d7d3fc31a122fe |
|
| /// File Name: |
ZDI-07-057.txt |
Description:
|
A vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Firebird SQL server. Authentication is not required to exploit this vulnerability. The specific flaw exists within the database service fbserver.exe, which binds to TCP port 3050. When processing an overly long request, a stack buffer can be overflowed through a vulnerable call to sprintf() within the function process_packet(). If properly exploited, remote control of the affected system can be attained with SYSTEM credentials.
| | Homepage: | http://www.zerodayinitiative.com/ | | File Size: | 3203 | | Related CVE(s): | CVE-2007-4992 | | Last Modified: | Oct 11 00:24:54 2007 |
| MD5 Checksum: | b5735efeaeed792730317961bd7ea7bf |
|
| /// File Name: |
sa27256.txt |
Description:
|
Secunia Security Advisory - Fedora has issued an update for epiphany-extensions. This package has been rebuilt against a new version of the firefox package. This fixes some vulnerabilities and weaknesses, which can be exploited by malicious people to disclose sensitive information, conduct phishing attacks, manipulate certain data, and potentially compromise a user's system.
| | Homepage: | http://secunia.com/advisories/27256/ | | File Size: | 3203 | | Last Modified: | Oct 25 16:56:56 2007 |
| MD5 Checksum: | 1181039552035e66344215cece3207fd |
|
| /// File Name: |
dsa-1389-2.txt |
Description:
|
Debian Security Advisory 1389-2 - It was discovered that zoph, a web based photo management system, performs insufficient input sanitizing, which allows SQL injection. This is an updated advisory to make the update for oldstable (sarge) available, which had been uploaded to the wrong suite.
| | Homepage: | http://www.debian.org/security | | File Size: | 3200 | | Related CVE(s): | CVE-2007-3905 | | Last Modified: | Oct 25 00:19:22 2007 |
| MD5 Checksum: | 39d2edf9a72cdbfb3b211bc4be0800d3 |
|
| /// File Name: |
glsa-200710-19.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200710-19 - Jean-Sebastien Guay-Leroux reported an integer underflow in the file_printf() function of the file utility which is bundled with The Sleuth Kit (CVE-2007-1536, GLSA 200703-26). Note that Gentoo is not affected by the improper fix for this vulnerability (identified as CVE-2007-2799, see GLSA 200705-25) since version 4.20 of file was never shipped with The Sleuth Kit ebuilds. Versions less than 2.0.9 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 3198 | | Related CVE(s): | CVE-2007-1536, CVE-2007-2799 | | Last Modified: | Oct 18 18:40:06 2007 |
| MD5 Checksum: | ca4f37a7a61ecbe504c0403c1b6e6772 |
|
| /// File Name: |
glsa-200710-24.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200710-24 - iDefense Labs reported that the TIFF parsing code uses untrusted values to calculate buffer sizes, which can lead to an integer overflow resulting in heap-based buffer overflow. Versions less than 2.3.0 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 3196 | | Related CVE(s): | CVE-2007-2834 | | Last Modified: | Oct 23 14:18:08 2007 |
| MD5 Checksum: | 73aa4f72707125b1dd6bf01f1f1085c5 |
|
| /// File Name: |
sa27271.txt |
Description:
|
Secunia Security Advisory - SUSE has issued an update for multiple packages. This fixes some vulnerabilities, which can be exploited by malicious, local users to bypass certain security restrictions or gain escalated privileges, and by malicious people to conduct spoofing attacks, cause a DoS (Denial of Service), and potentially compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/27271/ | | File Size: | 3192 | | Last Modified: | Oct 22 18:54:34 2007 |
| MD5 Checksum: | f53b4d5547947e1d70d012f872311be7 |
|
| /// File Name: |
sa26987.txt |
Description:
|
Secunia Security Advisory - SUSE has issued updates for multiple packages. This fixes some security issues and vulnerabilities, which can be exploited by malicious, local users to gain escalated privileges, by malicious users to cause a DoS (Denial of Service), bypass certain security restrictions, gain escalated privileges, and compromise a vulnerable system, and by malicious people to cause a DoS or compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/26987/ | | File Size: | 3167 | | Last Modified: | Oct 1 23:39:22 2007 |
| MD5 Checksum: | 8e786d2fa91ad8c32a3aa10882652050 |
|
| /// File Name: |
10.02.07-2.txt |
Description:
|
iDefense Security Advisory 10.02.07 - Local exploitation of an integer signedness error in Sun Microsystem's Solaris could allow attackers to disclose sensitive information from memory. iDefense has confirmed the existence of this vulnerability in Solaris 10 on x86 and SPARC. It is suspected that earlier versions are also affected.
| | Homepage: | http://www.idefense.com/ | | File Size: | 3165 | | Last Modified: | Oct 3 19:23:17 2007 |
| MD5 Checksum: | 9404e9c2ad59fb451666c20c0f9a20c7 |
|
| /// File Name: |
ZDI-07-059.txt |
Description:
|
Several vulnerabilities exist in the popular Verity KeyView SDK used in many enterprise applications like IBM Lotus Notes. When parsing several different file formats a standard stack overflow occurs allowing a malicious user to gain complete control of the affected machine under the rights of the currently logged in user. The problem lies when copying user supplied data to a stack based buffer without any boundary conditions.
| | Author: | Eric DETOISIEN | | Homepage: | http://www.zerodayinitiative.com/ | | File Size: | 3161 | | Last Modified: | Oct 31 20:08:53 2007 |
| MD5 Checksum: | d3b624150690115c6237f1905a92f447 |
|
|
|
|
|