GLSA: libpng

2003-01-15 Thread Daniel Ahlberg
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - GENTOO LINUX SECURITY ANNOUNCEMENT 200301-7 - - PACKAGE : libpng SUMMARY : buffer overflow DATE    :

Buffer Overflow in uucp of SunOS 5.8

2003-01-15 Thread hipnosis hipnosis
Hi everybody Though I dont know if this vulnerability has be discovered previously I found a buffer overflow in the app uucp of SunOS 5.8 that it could be used to get privileges of uucp. Buffer is overflow when the app uucp is executed with the parameter -s continued of a string

Re: IMP 2.x SQL injection vulnerabilities

2003-01-15 Thread Sylvain Robitaille
On Wed, 8 Jan 2003, Jouko Pynnonen informed us that: The vendor has been informed about this bug last month. Although there hasn't been any direct reply, there was a comment on this on the IMP mailing list: 2.2.x is officially deprecated/unsupported. This does not apply to 3.x.. Versions

Bug in w-agora

2003-01-15 Thread sonyy
=== ==Shell Security Team== === == Advisory For W-agora== == - Product : w-agora - Tested version : version 4.1.5 - Website : http://www.w-agora.net - Discovery By Sonyy - Vendor

MDKSA-2003:002 - Updated xpdf packages fix integer overflow vulnerability

2003-01-15 Thread Mandrake Linux Security Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Mandrake Linux Security Update Advisory Package name: xpdf Advisory ID:

MDKSA-2003:005 - Updated leafnode packages fix remote DoS vulnerability

2003-01-15 Thread Mandrake Linux Security Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Mandrake Linux Security Update Advisory Package name: leafnode Advisory ID:

[SECURITY] [DSA 224-1] New canna packages fix buffer overflow and denial of service

2003-01-15 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 224-1 [EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze January 8th, 2002

Request for assistance: trying to find Zardoz Security Digest Files

2003-01-15 Thread Curator at The 'Security Digest' Archives
I am the owner of a project designed to preserve computer security digests and I need to ask the community for help locating material relating to the Zardoz Security Digest. Without this material, I am not able to comprehensively document the history of this digest. In particular, I am unable

Re: Opentype font file causes Windows to restart.

2003-01-15 Thread dildog
I suppose that IE's 'automatic font download' support (which is on by default) would exacerbate this problem, correct? --dil

Re: Efficient Networks 5861 DSL Router

2003-01-15 Thread Andrew Hodgson
On Fri, 10 Jan 2003 11:05:01 -, Greg Bolshaw [EMAIL PROTECTED] wrote: Product: Efficient Networks 5861 DSL Router http://www.efficient.com/ebz/5800.html Tested version:5.3.80 (Latest firmware) Advisory date: 10/01/2003 Severity:

[SECURITY] [DSA 225-1] New tomcat packages fix source disclosure vulnerability

2003-01-15 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 225-1 [EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze January 9th, 2002

[RHSA-2002:295-07] Updated CUPS packages fix various vulnerabilities

2003-01-15 Thread bugzilla
- Red Hat, Inc. Red Hat Security Advisory Synopsis: Updated CUPS packages fix various vulnerabilities Advisory ID: RHSA-2002:295-07 Issue date:2003-01-13 Updated on:2003-01-09

[RHSA-2002:283-09] Updated cyrus-sasl packages fix buffer overflows

2003-01-15 Thread bugzilla
- Red Hat, Inc. Red Hat Security Advisory Synopsis: Updated cyrus-sasl packages fix buffer overflows Advisory ID: RHSA-2002:283-09 Issue date:2003-01-07 Updated on:2003-01-06

MDKSA-2003:004 - Updated KDE packages fix multiple vulnerabilities

2003-01-15 Thread Mandrake Linux Security Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Mandrake Linux Security Update Advisory Package name: kde Advisory ID:

E-theni (PHP)

2003-01-15 Thread Frog Man
Informations : °° Version : ? Website : http://www.theni.freesurf.fr Problems : - Include file - phpinfo() PHP Code/Location : °°° /admin_t/include/aff_liste_langue.php : - require ($rep_include.para_langue.php);

Re: A security vulnerability in S8Forum

2003-01-15 Thread David Wilson
On Tue, 2003-01-07 at 03:20, Steve Watt wrote: In article [EMAIL PROTECTED] you write: [ snip ] SOLUTION : == [ snip ] if(!eregi(^[_a-z0-9-]+(\.[_a-z0-9-]+)*@[a-z0-9-]+(\.[a-z0-9-]+)*(\.[a-z]{2,3})$, $email) $email != ) { Please note that there are many more characters

RE: Opentype font file causes Windows to restart.

2003-01-15 Thread Ben Naylor
Tested on Windows NT4 SP6a. Had to force opening with fontview as it was not associated by default. No restart, just message Not a valid font file. -Original Message- From: Andrew [mailto:[EMAIL PROTECTED]] Sent: 06 January 2003 15:37 To: [EMAIL PROTECTED]; [EMAIL PROTECTED] Subject:

Vulnerability in WebCollection Plus (TM)

2003-01-15 Thread f0urtyfive
These vulnerabilities were found / tested on: WebCollection Plus (TM) Copyright 2001 Follett Software Company Version 5.00 Revision 12-01-A Dec 19 2001 Program protects from reading other non-webserver accessible files by checking for a : or excessive .'s in a string. If the URL has a / at the

Re: ps information leak in FreeBSD

2003-01-15 Thread David M. Wilson
On Thu, Jan 09, 2003 at 02:48:30PM +1100, Damien Miller wrote: Crist J. Clark wrote: Any program that asks for a password on the command line should have the common decency to overwrite/obfuscate it, along the lines of, case 'p': passwd = optarg; optarg =

[INetCop Security Advisory] Remote format string vulnerability in Tanne.

2003-01-15 Thread dong-h0un yoU
INetCop Security Advisory #2003-0x82-012 * Title: Remote format string vulnerability in Tanne. 0x01. Description About: tanne is a small, secure session-management solution for HTTP.

RE: Opentype font file causes Windows to restart.

2003-01-15 Thread Discini, Sonny
Windows98 - No reboot. -Original Message- From: Andrew [mailto:[EMAIL PROTECTED]] Sent: Monday, January 06, 2003 10:37 AM To: [EMAIL PROTECTED]; [EMAIL PROTECTED] Subject: Opentype font file causes Windows to restart. Problem --- The attached OpenType font file will cause Windows

SuSE Security Announcement: libpng (SuSE-SA:2003:0004)

2003-01-15 Thread Thomas Biege
-BEGIN PGP SIGNED MESSAGE- __ SuSE Security Announcement Package:libpng Announcement-ID:SuSE-SA:2003:0004 Date: Tuesday,

Multiple Vulnerabilities in Sendmail on IRIX

2003-01-15 Thread SGI Security Coordinator
-BEGIN PGP SIGNED MESSAGE- __ SGI Security Advisory Title: Multiple Vulnerabilities in Sendmail Number : 20030101-01-P Date : January 6, 2003 Reference: CVE CAN-2002-1165

Re: Opentype font file causes Windows to restart.

2003-01-15 Thread Kaspar Brand
[Since my first attempt yesterday was not approved by the BugTraq moderator, I'm trying it again, this time in a slightly different format and CC'ing vulnwatch, too.] The problem is due to incorrect data in the CFF table of this font - for details, please see the attached message I sent to the

BitKeeper remote shell command execution/local vulnerability

2003-01-15 Thread Maurycy Prodeus
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Synopsis:BitKeeper remote shell command execution/local vulnerability Product: BitKeeper (http://www.bitkeeper.com) Version: 3.0.x Author: Maurycy Prodeus [EMAIL PROTECTED] Date:11 November 2002 Issue: - -- BitKeeper is

middleman-1.2 and prior off-by-one bug

2003-01-15 Thread qitest1
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 QITEST1 SECURITY ADVISORY #006 middleman-1.2 and prior off-by-one bug PROGRAM DESCRIPTION Middleman is a powerful proxy server with many features designed to make browsing the Internet a more pleasant experience. It can do much more than