MDKSA-2003:066 - Updated kernel packages fix multiple vulnerabilities

2003-06-11 Thread Mandrake Linux Security Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Mandrake Linux Security Update Advisory Package name: kernel Advisory ID:

Re: Etherleak information leak in Windows Server 2003 drivers

2003-06-11 Thread Ofir Arkin
Chris, The original Etherleak paper which was written by myself and Josh Anderson specifically states that: "The Ethernet standards impose strict limitations on the size of encapsulated packets, requiring small packets to be padded up to a minimum size. Many device drivers responsible for E

Denial of Service Attack against ArGoSoft Mail Server Version 1.8

2003-06-11 Thread [EMAIL PROTECTED]
TA-2003-06 Denial of Service Attack against ArGoSoft Mail Server Version 1.8 (1.8.3.5) contributed by: rushjo == Tripbit Security Advisory TA-2003-06 Denial of Service Attack against ArGoSoft Mail Server Version

Low risk vulnerabilities in ftp file list handling

2003-06-11 Thread alan
Several ftp parsing libraries are vulnerable to attack by simply feeding them too much data. While the library authors have taken care to be robust in parsing ftp NLST returns they don't iterate the data as they receive it but store the data until the NLST completes. In the case of rpm a user usin

[OpenPKG-SA-2003.031] OpenPKG Security Advisory (gzip)

2003-06-11 Thread OpenPKG
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 OpenPKG Security AdvisoryThe OpenPKG Project http://www.openpkg.org/security.html http://www.openpkg.org [EMAIL PROTECTED]