SuSE Security Announcement: syslog-ng (SuSE-SA:2002:039)

2002-10-31 Thread Sebastian Krahmer
-BEGIN PGP SIGNED MESSAGE- __ SuSE Security Announcement Package:syslog-ng Announcement-ID:SuSE-SA:2002:039 Date: Thu Oct

Motorola Cable Modem DOS

2002-10-31 Thread Ryan Sweat
I've found it trivial to crash the Motorola Surfboard 4200 Cable modem, as installed default by AT&T Broadband Internet. The modem acts as a bridge, but also has an internal RFC1918 IP address (192.168.100.1). Simply nmap'ing the cable user's IP address, ie: # nmap -sS -p 1-1024 12.x.x.x will ca

RE: IBM Infoprint Remote Management Simple DoS (update)

2002-10-31 Thread Toni Lassila
UPDATE: It appears this vulnerability has been rectified in later versions of the printer controller software. As it stands, printers installed with the controller software above a certain version are NOT vulnerable, and it appears the latest Infoprint series printers are indeed not vulnerable. Th

Cisco Security Advisory: Cisco ONS15454 and Cisco ONS15327 Vulnerabilities

2002-10-31 Thread Cisco Systems Product Security Incident Response Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Cisco Security Advisory: Cisco ONS15454 and Cisco ONS15327 Vulnerabilities Revision 1.0 For Public Release 2002 October 31 at 1600 UTC -- Contents Summary Affected

Re: Gimp: Erased sections of images print in some cases

2002-10-31 Thread Earl Hood
On October 30, 2002 at 11:08, Clark Mills wrote: >As part of documenting processes, I take screen captures and then chop >stuff out that I don't want the world to see. I do this within the Gimp >by setting an alpha channel on the screen capture and then _erasing_ the >parts of the image that I wa

MDKSA-2002:074 - mozilla update

2002-10-31 Thread Mandrake Linux Security Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Mandrake Linux Security Update Advisory Package name: mozilla Advisory ID:

Security Update: [CSSA-2002-043.0] Linux: chfn (util-linux) temp file race vulnerability

2002-10-31 Thread security
To: [EMAIL PROTECTED] [EMAIL PROTECTED] [EMAIL PROTECTED] [EMAIL PROTECTED] __ SCO Security Advisory Subject:Linux: chfn (util-linux) temp file race vulnerability Advisory number

Re: Bypassing website filter in SonicWall

2002-10-31 Thread Robert Bihlmeyer
Marc Ruef <[EMAIL PROTECTED]> writes: > I found a little weakness in SonicWall: I turn on the blocking > mechanism for websites (e.g. www.google.com). Now I can't reach the > website using the domainname. But if I choose the IP address of the > host (e.g. http://216.239.53.101/), I can contact the

Anyone know the security alert contact for 3com?

2002-10-31 Thread Michael Scheidell
We need to contact 3com about a potential security problem with one of their products and wanted to know if they had an official email address for such communications. -- Michael Scheidell SECNAP Network Security, LLC Sales: 866-SECNAPNET / (1-866-732-6276) Main: 561-368-9561 / www.secnap.net Lo

Microsoft Internet Information Server 5/5.1 Denial of Service (#NISR31102002)

2002-10-31 Thread NGSSoftware Insight Security Research
NGSSoftware Insight Security Research Advisory Name:IIS 5 & 5.1 Denial Of Service Vulnerability Systems Affected: Windows 2000 and XP all service packs. Severity: Moderate Category: Denial of Service Vendor URL: http://www.mircosoft.com Author: Mark Litchfield ([EMAIL PROTE

SuSE Security Announcement: lprng/html2ps (SuSE-SA:2002:040)

2002-10-31 Thread Sebastian Krahmer
-BEGIN PGP SIGNED MESSAGE- __ SuSE Security Announcement Package:lprng, html2ps Announcement-ID:SuSE-SA:2002:040 Date: Th

SmartMail server DOS

2002-10-31 Thread securma massine
hi SmartMail Server ( http://www.virtualzone.de/smartmail/)is a full featured E-Mail Server. It can be run on any 32Bit compatible Microsoft Windows machine and complies with the standards of SMTP, POP3 and HTTP (Webinterface). SmartMail proposes two version of SmartMail server, I found that two v

[SECURITY] [DSA 185-1] New heimdal packages fix buffer overflows

2002-10-31 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 185-1 [EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze October 31st, 2002