Re: @(#)Mordred Labs advisory 0x0003: Buffer overflow in PostgreSQL

2002-08-21 Thread Florian Weimer
Sir Mordred The Traitor <[EMAIL PROTECTED]> writes: > --[ Solution > > Do you still running postgresql? ...Can't believe that... > If so, execute the following command as a root: "killall -9 postmaster", > and wait until the patch will be available. There's no need for such drastic action. Exec

[RHSA-2002:109-07] Updated bugzilla packages fix security issues

2002-08-21 Thread bugzilla
- Red Hat, Inc. Red Hat Security Advisory Synopsis: Updated bugzilla packages fix security issues Advisory ID: RHSA-2002:109-07 Issue date:2002-06-09 Updated on:2002-08-20 Product

Win32 API 'shatter' vulnerability found in VNC-based products

2002-08-21 Thread EXT-Bellers, Chris
Win32 API 'shatter' vulnerability found in VNC-based products CONFIRMED PROGRAMS: VNC v3.3.3R9 TightVNC v1.2.5 TridiaVNC 1.5.4 SUSPECTED PROGRAMS: TridiaVNC Pro All other VNC-based remote console products EXPLOIT TYPE: 'Shatter'-type win32-based local privilege escalation (See: http://securit

LG Electronics LG3001f router

2002-08-21 Thread Bromirski, Lukasz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Issue: | LG Electronics LR3001f is a WAN router. It comes with no access lists defined, which enables administrator to connect both to port 23/tcp (telnet) and 80/tcp (www server). H

More Vulnerabilities with Pingtel xpressa SIP-based IP phones

2002-08-21 Thread Ofir Arkin
The Sys-Security Group Security Advisory "More Vulnerabilities with Pingtel xpressa SIP-based IP Phones" Release Date: 08/20/2002 Affected Platforms: Pingtel xpressa SIP IP phones model PX-1 with software version 2.0.1 and below; Pingtel instant xpressa softphones with software version 2.0.1 an

bugtraq@security.nnov.ru list issues [2]

2002-08-21 Thread 3APA3A
Dear [EMAIL PROTECTED], There are few issues reported to [EMAIL PROTECTED] list in Russian during last months. This issues have no relation to SECURITY.NNOV team. Please contact authors directly if you have any questions. 1. Eraser reports vulnerabilities in Aquonics File Mana

Solaris 2.6-8 SPARC Telnetd Vulnerability

2002-08-21 Thread Brendan C. Johnson
Affected Systems: Solaris 2.6, 2.7, 8 SPARC Platform Remote & Local Exploit #include #include #include #include #include #include #include #include #include #ifdef SOLARIS typedef unsigned long u_int32_t; #endif #define BUFLEN 1024 char shellcode[]= "\x21\x0b\xd8\x9a\xa0\x14\x21\x6

More DBCC overruns SQL SEVER 2000

2002-08-21 Thread Mark Litchfield
To compliment http://online.securityfocus.com/archive/1/284382/2002-07-20/2002-07-26/0 there also exists another two bufferoverruns. Although not documented on MS they are fixed in http://download.microsoft.com/download/SQLSVR2000/Patch/8.00.0667/W98NT4 2KMeXP/EN-US/8.00.0667_enu.exe 1) DBCC buf

Re: Solaris 2.6-8 SPARC Telnetd Vulnerability

2002-08-21 Thread Casper Dik
>Affected Systems: Solaris 2.6, 2.7, 8 SPARC Platform Theis appears to be an exploit exploiting the combination of the bugs: 4516876 in.telnetd should not accept TTYPROMPT from remote 4516885 *login* security problem Patches that fix the login problem: 105665-04: SunOS 5.6: /usr/bin/login pat

NOVL-2002-2963349 - Rconag6 Secure IP Login Vulnerability -NW6SP2

2002-08-21 Thread Ed Reed
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 For Immediate Disclosure == Summary == Security Alert: NOVL-2002-2963349 Title: Rconag6 Secure IP Login Vulnerability - NW6SP2 Date: 21-Aug-2002 Revision: Original

Re: @(#)Mordred Labs advisory 0x0003: Buffer overflow in PostgreSQL

2002-08-21 Thread Lamar Owen
On Tuesday 20 August 2002 10:28 am, Sir Mordred The Traitor wrote: > --[ Solution > > Do you still running postgresql? ...Can't believe that... > If so, execute the following command as a root: "killall -9 postmaster", > and wait until the patch will be available. This is irresponsible advice, as

[RHSA-2002:158-09] New kernel update available, fixes i810 video oops, several security issues

2002-08-21 Thread bugzilla
- Red Hat, Inc. Red Hat Security Advisory Synopsis: New kernel update available, fixes i810 video oops, several security issues Advisory ID: RHSA-2002:158-09 Issue date:2002-07-26 Update

WorldView vulnerability on IRIX

2002-08-21 Thread SGI Security Coordinator
-BEGIN PGP SIGNED MESSAGE- __ SGI Security Advisory Title: WorldView vulnerability Number: 2803-01-P Date: August 21, 2002 Reference: SGI Securit