[CLA-2003:693] Conectiva Security Announcement - pam

2003-07-10 Thread Conectiva Updates
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- CONECTIVA LINUX SECURITY ANNOUNCEMENT - -- PACKAGE : pam SUMMARY : Local vulnerability in the pam

PHP-Include-Hack-Possibility in phpforum 2 RC-1

2003-07-10 Thread theblacksheep
<> <#www.bright-shadows.net#> <> <--#theblacksheep&erik#--> <

Re: ServU FTP Service (Win32) is able to relay email

2003-07-10 Thread Hal Flynn
> ServU FTP Server for Win32 has a Bug that makes it possible to relay > email messages anonymously. As described in the RFC documents for FTP > (959, 1579, 2228) its not recommendet for the service to accept PORT > commands containing target ports above 1024/tcp. Example: Nice. I'd like to point

[SCSA-019] Gattaca Server 2003 Vulnerable to Multiple vulnerabilities

2003-07-10 Thread Gregory LEBRAS
= Security Corporation Security Advisory [SCSA-019] Gattaca Server 2003 Vulnerable to Multiple vulnerabilities = PROGRAM: Gattaca Server 2003 HOMEPAGE: www.gat

[OpenPKG-SA-2003.033] OpenPKG Security Advisory (infozip)

2003-07-10 Thread OpenPKG
: Affected Packages: Corrected Packages: OpenPKG CURRENT <= infozip-20030306-20030708 >= infozip-20030710-20030710 OpenPKG 1.2 <= infozip-1.2.0-1.2.0 >= infozip-1.2.0-1.2.1 OpenPKG 1.1 <= infozip-1.1.0-1.1.0 >= infozip-1.1.0-1.1.1 Depende

[OpenPKG-SA-2003.034] OpenPKG Security Advisory (imagemagick)

2003-07-10 Thread OpenPKG
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 OpenPKG Security AdvisoryThe OpenPKG Project http://www.openpkg.org/security.html http://www.openpkg.org [EMAIL PROTECTED]

Acroread 5.0.7 buffer overflow

2003-07-10 Thread Paul Szabo
I. BACKGROUND Acroread from http://www.adobe.com is the pre-eminent PDF file viewer. The latest version Acroread 5.0.7 for Linux was released on 17 June 2003. II. DESCRIPTION Despite recent security fixes, an exploitable buffer overflow with long URL strings remains. The overflow occurs when you

Re: PalmOS Memo Record Hiding Vulnerability.

2003-07-10 Thread Goetz Bock
> -[BACKGROUND]-: > > PalmOS includes a pre-installed 'Security' > Application, which allows a Palm enabled device to add > weak security, to hide data and protect the PDA from > casual snoopers. One particular feature is the > ability to "Hide" Memos set as "Private" in the > Security section o