GLSA: MailTools

2002-11-06 Thread Daniel Ahlberg
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - GENTOO LINUX SECURITY ANNOUNCEMENT 200211-001 - - PACKAGE : MailTools SUMMARY : remote command execution

[SECURITY] [DSA 189-1] New luxman packages fix local root exploit

2002-11-06 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 189-1 [EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze November 6th, 2002

[CLA-2002:539] Conectiva Linux Security Announcement - ypserv

2002-11-06 Thread secure
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- CONECTIVA LINUX SECURITY ANNOUNCEMENT - -- PACKAGE : ypserv SUMMARY : Ypserv memory leak DATE

[CLA-2002:541] Conectiva Linux Security Announcement - mod_ssl

2002-11-06 Thread secure
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- CONECTIVA LINUX SECURITY ANNOUNCEMENT - -- PACKAGE : mod_ssl SUMMARY : Cross site scripting

[CLA-2002:540] Conectiva Linux Security Announcement - heartbeat

2002-11-06 Thread secure
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- CONECTIVA LINUX SECURITY ANNOUNCEMENT - -- PACKAGE : heartbeat SUMMARY : Remote format string

[CLA-2002:537] Conectiva Linux Security Announcement - tetex

2002-11-06 Thread secure
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- CONECTIVA LINUX SECURITY ANNOUNCEMENT - -- PACKAGE : tetex SUMMARY : dvips command execution

[CLA-2002:534] Conectiva Linux Security Announcement - krb5

2002-11-06 Thread secure
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- CONECTIVA LINUX SECURITY ANNOUNCEMENT - -- PACKAGE : krb5 SUMMARY : Buffer overflow

[CLA-2002:542] Conectiva Linux Security Announcement - gv/kghostview

2002-11-06 Thread secure
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- CONECTIVA LINUX SECURITY ANNOUNCEMENT - -- PACKAGE : gv/kghostview SUMMARY : Buffer overflow

[CLA-2002:538] Conectiva Linux Security Announcement - tar/unzip

2002-11-06 Thread secure
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- CONECTIVA LINUX SECURITY ANNOUNCEMENT - -- PACKAGE : tar/unzip SUMMARY : Directory transversal

[CLA-2002:535] Conectiva Linux Security Announcement - glibc

2002-11-06 Thread secure
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- CONECTIVA LINUX SECURITY ANNOUNCEMENT - -- PACKAGE : glibc SUMMARY : Fix for several

iDEFENSE Security Advisory 11.06.02: Non-Explicit Path Vulnerability in LuxMan

2002-11-06 Thread David Endler
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 iDEFENSE Security Advisory 11.06.02: http://www.idefense.com/advisory/11.06.02.txt Non-Explicit Path Vulnerability in LuxMan November 6, 2002 I. BACKGROUND Frank McIngvale's LuxMan is a Linux-based game similar to Pac Man. More information about it

Re: [Full-Disclosure] Re: Oracle Security Contact

2002-11-06 Thread Chris Wysopal
There is a list of vendor contacts maintained by VulnWatch to assist our readers: http://www.vulnwatch.org/links.html There you will find product security email contacts and links to vendor security bulletin archives. Updates or new contact information welcome. Please mail [EMAIL PROTECTED]

QNX 6.1 TimeCreate weakness

2002-11-06 Thread Pawel Pisarczyk
I've found bug in QNX-6.1 timer implementation. After creating some number (at least 2) of timers with 1 ms tick system hangs. Please consider attached source code. Code can be executed by unprivilegged users. Pawel Pisarczyk IMMOS - IMMOrtal Systems /* * QNX RTP

How to execute programs with parameters in IE - Sandblad advisory#10

2002-11-06 Thread Andreas Sandblad
- Sandblad advisory #10 - Title: How to execute programs with parameters in IE Date: [2002-11-06] Software: Internet Explorer (webbrowser control) Vendor: http://www.microsoft.com/ Impact:

[CLA-2002:544] Conectiva Linux Security Announcement - linuxconf

2002-11-06 Thread secure
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- CONECTIVA LINUX SECURITY ANNOUNCEMENT - -- PACKAGE : linuxconf SUMMARY : Open relay in mailconf

Re: Oracle Security Contact

2002-11-06 Thread Steven M. Christey
On the full-disclosure list, low halo asked: Could someone please give me the security contact address for Oracle Corporation? It seems as though their marketing department's Unbreakable slogan makes them think that its OK to bury their security advisories contact info deep within their site