Re: Xaraya <= 1.0.0 RC4 D.O.S / file corruption

2005-11-30 Thread Paul Laudanski
On 29 Nov 2005 [EMAIL PROTECTED] wrote: > Xaraya <= 1.0.0 RC4 D.O.S / file corruption > > software: > site: http://www.xaraya.com > description: "Xaraya 1.0 Core is an Open Source web application framework > written in PHP" > i) you can create an empty dir, in some cases this leads to D.O.S. > c

Re: WebCalendar Multiple Vulnerabilities

2005-11-30 Thread ascii
Paul Laudanski wrote: I too tried contacting the vendor but received no response. Your timing of vendor notice and vul'n release are fast unfortunately. Taking a look, simple functions in PHP can be called upon to fix those issues. thanks Paul for the cooperation : ) i'm sorry i hadn't upda

Re: DNS query spam

2005-11-30 Thread Florian Weimer
* Josep Ma Castells: > I have the same problem, now I'm blocking this attempts with iptables and > the Recent module when a number of tries is reached. > > This is the content of the packet: > =+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+ > > 11/20/05-19:17:37.177173

Re: DNS query spam

2005-11-30 Thread Jim Pingle
Florian Weimer wrote: > * Piotr Kamisiski: > > >>23:05:40.241026 IP 204.92.73.10.40760 > xx.xx.xx.xx.53: 38545+ [1au] ANY >>ANY? e.mpisi.com. (40) > > > > 204.92.73.10 is one of the IP addresses for irc.efnet.ca. Someone is > spoofing the source addresses, in the hope that DNS servers will

MDKSA-2005:219 - Updated kernel packages fix numerous vulnerabilities

2005-11-30 Thread Mandriva Security Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDKSA-2005:219 http://www.mandriva.com/security/

MDKSA-2005:218 - Updated kernel packages fix numerous vulnerabilities

2005-11-30 Thread Mandriva Security Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDKSA-2005:218 http://www.mandriva.com/security/

Re: Opera 8.50 DoS with simple java applet

2005-11-30 Thread Edward D Wiget
On Tuesday 29 November 2005 06:31 pm, Marc Schoenefeld wrote: > Hi y'all, > > it is possible to crash the opera 8.50 browser with a simple > java applet (see below). > This was observed on Win32, Linux versions maybe affected, too. verified on gentoo linux, opera 8.50 and here is the results: An

MDKSA-2005:217 - Updated netpbm packages fix pnmtopng vulnerabilities

2005-11-30 Thread Mandriva Security Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDKSA-2005:217 http://www.mandriva.com/security/

MDKSA-2005:220 - Updated kernel packages fix numerous vulnerabilities

2005-11-30 Thread Mandriva Security Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDKSA-2005:220 http://www.mandriva.com/security/