McAfee ePolicy Orchestrator Format String Vulnerability (a031703-1)

2003-03-17 Thread @stake Advisories
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 @stake, Inc. www.atstake.com Security Advisory Advisory Name: ePolicy Orchestrator Format String Vulnerability Release Date: 03/17/2003 Application: McAfee ePolicy

MITKRB5-SA-2003-004: Cryptographic weaknesses in Kerberos v4protocol

2003-03-17 Thread Tom Yu
-BEGIN PGP SIGNED MESSAGE- MIT krb5 Security Advisory 2003-004 2003-03-17 Topic: Cryptographic weaknesses in Kerberos v4 protocol Severity: CRITICAL SUMMARY === A cryptographic weakness in version 4 of the Kerberos protocol allows an attacker to use a

[SECURITY] [DSA 263-1] New tcpdump packages fix denial of service vulnerability

2003-03-17 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 263-1 [EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze March 17th, 2003

[RHSA-2003:098-00] Updated 2.4 kernel fixes vulnerability

2003-03-17 Thread bugzilla
- Red Hat Security Advisory Synopsis: Updated 2.4 kernel fixes vulnerability Advisory ID: RHSA-2003:098-00 Issue date:2003-03-17 Updated on:2003-03-17 Product: Red Hat

SPI ADVISORY: Remote Administration of BEA WebLogic Server and Express

2003-03-17 Thread Caleb Sima
Remote Administration of BEA WebLogic Server and Express Release Date: March 18, 2003 Severity: High Systems Affected: • WebLogic Server and Express 6.0 • WebLogic Server and Express 6.1 • WebLogic Server and Express 7.0 Description: SPI Labs and S21sec have identified a

[INetCop Security Advisory #2002-0x82-013] Kebi Academy 2001 Web Solution Directory Traversing Vulnerability.

2003-03-17 Thread dong-h0un U
INetCop Security Advisory #2002-0x82-013 * Title: Kebi Academy 2001 Web Solution Directory Traversing Vulnerability. 0x01. Description Kebi Academy 2001 is web solution that is

GLSA: samba (200303-11)

2003-03-17 Thread Daniel Ahlberg
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - - GENTOO LINUX SECURITY ANNOUNCEMENT 200303-11 - - - PACKAGE : samba SUMMARY : buffer

[ADVISORY] Timing Attack on OpenSSL

2003-03-17 Thread Ben Laurie
I expect a release to follow shortly. -- http://www.apache-ssl.org/ben.html http://www.thebunker.net/ There is no limit to what a man can do or how far he can go if he doesn't mind who gets the credit. - Robert Woodruff OpenSSL v0.9.7a and 0.9.6i vulnerability

Security Bugfix for Samba - Samba 2.2.8 Released

2003-03-17 Thread Maslov, Snowy
(See http://www.samba.org/samba/whatsnew/samba-2.2.8.html for a copy of this information) The Samba Team announces Samba 2.2.8 * IMPORTANT: Security bugfix for Samba *

[RHSA-2003:072-08] Updated Gnome-lokkit packages fix vulnerability

2003-03-17 Thread bugzilla
- Red Hat Security Advisory Synopsis: Updated Gnome-lokkit packages fix vulnerability Advisory ID: RHSA-2003:072-00 Issue date:2003-03-17 Updated on:2003-03-17 Product:

GLSA: qpopper (200303-12)

2003-03-17 Thread Daniel Ahlberg
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - - GENTOO LINUX SECURITY ANNOUNCEMENT 200303-12 - - - PACKAGE : qpopper SUMMARY : buffer

[RHSA-2003:054-00] Updated rxvt packages fix various vulnerabilites

2003-03-17 Thread bugzilla
- Red Hat Security Advisory Synopsis: Updated rxvt packages fix various vulnerabilites Advisory ID: RHSA-2003:054-00 Issue date:2003-03-17 Updated on:2003-03-17 Product:

S21SEC-011 - Multiple vulnerabilities in BEA WebLogic Server

2003-03-17 Thread Lluis Mora
### ID: S21SEC-011-en Title: Multiple vulnerabilities in BEA WebLogic Server Date: 7/01/2003 Status: Patch published Scope: Remote command execution Platforms: Linux, Windows 2000, probably others Author: llmora Location:

[SCSA-010] Path Disclosure Cross Site Scripting Vulnerability in MyABraCaDaWeb

2003-03-17 Thread Grégory
Security Corporation Security Advisory [SCSA-010] PROGRAM: MyABraCaDaWeb HOMEPAGE: http://www.webmaster-mag.net/ VULNERABLE VERSIONS: v1.0.2 and

MDKSA-2003:032 - Updated samba packages fix remote root vulnerability

2003-03-17 Thread Mandrake Linux Security Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Mandrake Linux Security Update Advisory Package name: samba Advisory ID:

Re: qpopper timing analysis on to determine if a username exists on a system

2003-03-17 Thread Waldo Nell
Hi, I have tested this on my qpopper 4.0.5 - and I get this response no matter from which host I test (even localhost): sun waldo # ./poptest mail.XXX.net gert Validating username gert , please stand by.. Disconnected after 119.993 seconds. User gert is probably a valid user But that user is

PHP-Nuke 5.5 and 6.0: Path Disclosure

2003-03-17 Thread Rynho Zeros Web
+ Product - PHP-Nuke + Version - 5.5, 6.0 (other versions not tested jet) + Website - http://www.phpnuke.org + Problems - Path Disclosure + Explanation: The fault happens in the file print.php, which this including in the modulos 'News' and 'AvantGo', in the same one is checked that the

[Sorcerer-spells] SAMBA-SORCERER2003-03-17

2003-03-17 Thread Michael Walton
-- Michael Walton Asst-Manager Tech Support [EMAIL PROTECTED] (915)677-7900 Sorcerer Update Advisory Tap Into the Source Source Name:

CERT Advisory CA-2003-09 Buffer Overflow in Microsoft IIS 5.0 (fwd)

2003-03-17 Thread Dave Ahmad
David Mirza Ahmad Symantec sabbe dhamma anatta 0x26005712 8D 9A B1 33 82 3D B3 D0 40 EB AB F0 1E 67 C6 1A 26 00 57 12 ---BeginMessage--- -BEGIN PGP SIGNED MESSAGE- CERT Advisory CA-2003-09 Buffer Overflow in Microsoft IIS 5.0 Original issue date: March 17, 2003 Last

AOL's Billion SPAM March on Cyberspace

2003-03-17 Thread Jason Coombs
Aloha, Lonnie. Your article: ISPs Seek Bigger Mallet To Eliminate Spammers caught my attention. http://www.theledger.com/apps/pbcs.dll/section?Category=COLUMNISTS0203 I'm an information security and computer forensics expert with detailed technical knowledge of SPAM and the technology employed

Re: PROBLEMS WITH WINDOWS SHORTCUTS

2003-03-17 Thread Alexander Kiwerski
Verified on Windows XP Pro SP1. Crashes Explorer everytime. /Alex Kiwerski At 05:19 AM 3/15/2003 -0800, S G Masood wrote: PROBLEMS WITH WINDOWS SHORTCUTS == Topic: Problems with Windows Shortcuts