[ MDVSA-2009:053 ] squirrelmail

2009-02-25 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2009:053 http://www.mandriva.com/security/

Re: Another SQL injection in ProFTPd with mod_mysql (probably postgres as well)

2009-02-25 Thread Benjamin Milde
Reproduceable under Gentoo with Proftpd 1.3.1 - But not under debian etch with Proftpd 1.3.0 The newst Proftpd in Gentoo is 1.3.2-rc2, but there seems to be an Mysql-related patch in the build-file now. I also tested vanilla 1.3.2-rc4 and 1.3.2, with all three the sql-injection is not

Re: HP Quality Center vulnerability

2009-02-25 Thread Pavel Kankovsky
On Mon, 23 Feb 2009 i...@exposit.co.uk wrote: The front-end of the application is composed of COM components that plug into the web browser. [...] In order to optimize the interaction speed of the application, a cache folder is created on the client machine. [...] Indeed, those files are

pPIM Multiple Vulnerabilities

2009-02-25 Thread Justin C. Klein Keane
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -= pPIM Multiple Vulnerabilities =- Version Tested: pPIM 1.0 Vendor notified Full details can also be found at http://www.lampsecurity.org/node/18 Author: Justin C. Klein Keane jus...@madirish.net Description pPIM

[ MDVSA-2009:054 ] nagios

2009-02-25 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2009:054 http://www.mandriva.com/security/

Secunia Research: Orbit Downloader Long URL Parsing Buffer Overflow

2009-02-25 Thread Secunia Research
== Secunia Research 25/02/2009 - Orbit Downloader Long URL Parsing Buffer Overflow - == Table of Contents Affected

[security bulletin] HPSBMA02384 SSRT071465 rev.1 - HP OpenView Network Node Manager (OV NNM), Remote Unauthorized Access, Denial of Service (DoS)

2009-02-25 Thread security-alert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c01601492 Version: 1 HPSBMA02384 SSRT071465 rev.1 - HP OpenView Network Node Manager (OV NNM), Remote Unauthorized Access, Denial of Service (DoS) NOTICE: The information in this Security

[BMSA-2009-03] Multiple vulnerabilities in OpenSite v2.1

2009-02-25 Thread Nam Nguyen
BLUE MOON SECURITY ADVISORY 2009-03 === :Title: Multiple vulnerabilities in OpenSite v2.1 :Severity: Critical :Reporter: Blue Moon Consulting :Products: OpenSite v2.1 :Fixed in: to be fixed in 3.0 Description --- OpenSite is an Open Source Content

Apple Safari 4 Beta feeds: URI NULL Pointer Dereference Denial of Service Vulnerability

2009-02-25 Thread Trancer
Apple Safari 4 Beta feeds: URI NULL Pointer Dereference Denial of Service Vulnerability Date:Feb 25 2009 Class:Input Validation Error Local:Yes Remote:Yes Vulnerable Versions: * Apple Safari 4 (528.16) Public Beta Note: MacOS X versions not tested. Description: Apple Safari

[DSECRG-09-008] JOnAS(4.10.3) - Linked XSS Vulnerability

2009-02-25 Thread Digital Security Research Group
Digital Security Research Group [DSecRG] Advisory #DSECRG-09-008 --link to original advisory -- http://www.dsecrg.com/pages/vul/show.php?id=81 Application:JOnAS (Java Open Application Server) Versions Affected:

Secunia Research: SHOUTcast DNAS Relay Server Buffer Overflow

2009-02-25 Thread Secunia Research
== Secunia Research 25/02/2009 - SHOUTcast DNAS Relay Server Buffer Overflow - == Table of Contents Affected

Cisco Security Advisory: Cisco ACE Application Control Engine Device Manager and Application Networking Manager Vulnerabilities

2009-02-25 Thread Cisco Systems Product Security Incident Response Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Cisco Security Advisory: Cisco ACE Application Control Engine Device Manager and Application Networking Manager Vulnerabilities Advisory ID: cisco-sa-20090225-anm http://www.cisco.com/warp/public/707/cisco-sa-20090225-anm.shtml Revision 1.0

Cisco Security Advisory: Multiple Vulnerabilities in the Cisco ACE Application Control Engine Module and Cisco ACE 4710 Application Control Engine

2009-02-25 Thread Cisco Systems Product Security Incident Response Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Cisco Security Advisory: Multiple Vulnerabilities in the Cisco ACE Application Control Engine Module and Cisco ACE 4710 Application Control Engine Document ID: 109450 Advisory ID: cisco-sa-20090225-ace http://www.cisco.com/warp/public/707/cisco-sa

Secunia Research: ksquirrel-libs Radiance RGBE Buffer Overflows

2009-02-25 Thread Secunia Research
== Secunia Research 25/02/2009 - ksquirrel-libs Radiance RGBE Buffer Overflows - == Table of Contents Affected

Cisco Security Advisory: Cisco Unified MeetingPlace Web Conferencing Authentication Bypass Vulnerability

2009-02-25 Thread Cisco Systems Product Security Incident Response Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Cisco Security Advisory: Cisco Unified MeetingPlace Web Conferencing Authentication Bypass Vulnerability Advisory ID: cisco-sa-20090225-mtgplace Revision 1.0 For Public Release 2009 February 25 1600 UTC (GMT

[ MDVSA-2009:055 ] audacity

2009-02-25 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2009:055 http://www.mandriva.com/security/

[SECURITY] [DSA 1726-1] New python-crypto packages fix denial of service

2009-02-25 Thread Moritz Muehlenhoff
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - Debian Security Advisory DSA-1726-1 secur...@debian.org http://www.debian.org/security/ Moritz Muehlenhoff February 25, 2009