[ GLSA 200612-05 ] KOffice shared libraries: Heap corruption

2006-12-11 Thread Sune Kloppenborg Jeppesen
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200612-05 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - - -

[ MDKSA-2006:227 ] - Updated kdegraphics packages fix EXIF vulnerability

2006-12-11 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDKSA-2006:227 http://www.mandriva.com/security/ ___

Multiple vulnerabilities in Winamp Web Interface 7.5.13

2006-12-11 Thread Luigi Auriemma
### Luigi Auriemma Application: Winamp Web Interface http://www.flippet.org/wawi/ Versions: <= 7.5.13 Platforms:Windows (Winamp plugin) Bugs: A] buffer-overflow in Find

Secunia Research: AOL CDDBControl ActiveX Control "SetClientInfo()" Buffer Overflow

2006-12-11 Thread Secunia Research
== Secunia Research 08/12/2006 - AOL CDDBControl ActiveX Control "SetClientInfo()" Buffer Overflow - == Table of Co

[ GLSA 200612-03 ] GnuPG: Multiple vulnerabilities

2006-12-11 Thread Raphael Marichez
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200612-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - - -

[ GLSA 200612-07 ] Mozilla Firefox: Multiple vulnerabilities

2006-12-11 Thread Raphael Marichez
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200612-07 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - - -

RFID access control tokens widely open to cloning

2006-12-11 Thread Adam Laurie
Too many systems to itemize here rely on the 'unique ID' of an RFID token to grant access to a system or building, and, in the case that these tokens are based on 125kHz or 134.2kHz standard tags, many of them may be vulnerable to relatively simple cloning attacks. In a way this is nothing new

Re: LS-20060908 - Computer Associates BrightStor ARCserve Backup

2006-12-11 Thread Williams, James K
> List: bugtraq > Subject:LS-20060908 - Computer Associates BrightStor > ARCserve Backup > From: advisories () lssec ! com > Date: 2006-12-08 21:26:30 > > LS-20060908 > [...] > > Technical details: > > http://www.lssec.com/advisories.html > > LSsecurity - LS

The newest Word flaw is due to malformed data structure handling

2006-12-11 Thread Juha-Matti Laurio
Related to the newest MS Word 0-day http://blogs.technet.com/msrc/archive/2006/12/10/new-report-of-a-word-zero-day.aspx US-CERT Vulnerability Note VU#166700 released today lists the following new technical detail: "Microsoft Word fails to properly handle malformed data structures allowing memor

[ GLSA 200612-10 ] Tar: Directory traversal vulnerability

2006-12-11 Thread Matthias Geerdsen
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200612-10 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - - -

Re: LS-20061001 - Computer Associates BrightStor ARCserve Backup

2006-12-11 Thread Williams, James K
> List: bugtraq > Subject:LS-20061001 - Computer Associates BrightStor > ARCserve Backup > From: advisories () lssec ! com > Date: 2006-12-08 21:28:39 > > LS-20061001 > [...] > > Technical details: > > http://www.lssec.com/advisories.html > > LSsecurity - LSsec.c

Re: Another, different MS Word 0-day vulnerability reported

2006-12-11 Thread Juha-Matti Laurio
One of the links in previous message was erroneous, because MSRC Blog hyperlink pointed to the wrong URL. Correction follows: Microsoft has confirmed that it is a different vulnerability than this issue reported earlier this week: http://www.microsoft.com/technet/security/advisory/929433.mspx

Secunia Research: MailEnable IMAP Service Buffer Overflow Vulnerability

2006-12-11 Thread Secunia Research
== Secunia Research 11/12/2006 - MailEnable IMAP Service Buffer Overflow Vulnerability - == Table of Contents Affected Software..

[ GLSA 200612-06 ] Mozilla Thunderbird: Multiple vulnerabilities

2006-12-11 Thread Raphael Marichez
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200612-06 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - - -

shopsite advisory

2006-12-11 Thread DoZ
Hackers Center Security Group (http://www.hackerscenter.com/) Doz's Security Advisory Desc: ShopSite Shopping Cart Multiple XSS Risk: Medium ShopSite™ is the easiest-to-use shopping cart software for small to medium-sized businesses. ShopSite ecommerce shopping cart is one of the most user-frie

Several updates in Microsoft Word 0-day (CVE-2006-5994) FAQ document

2006-12-11 Thread Juha-Matti Laurio
Several updates have been done to "Microsoft Word 0-day Vulnerability FAQ - December 2006, CVE-2006-5994" document during the weekend. -added information about AV vendor protection -added information about the state of Internet threat meters -added several reference hyperlinks -detailed informat

looking for security community input

2006-12-11 Thread Gadi Evron
Hi guys. This January a couple hundred people from the net-ops world, anti virus, anti spam, law enforcement, etc. are getting together. I'd appreciate if any of you can send me input (off list, if not relevant to generate discussion) on what the security community at large, rather than just the

Another, different MS Word 0-day vulnerability reported

2006-12-11 Thread Juha-Matti Laurio
New vulnerability in Microsoft Word has been reported. More details available at SANS Internet Storm Center Diary: http://isc.sans.org/diary.php?storyid=1925 Microsoft has confirmed that it is a different vulnerability than this issue reported earlier this week: http://www.microsoft.com/security

[ GLSA 200612-08 ] SeaMonkey: Multiple vulnerabilities

2006-12-11 Thread Raphael Marichez
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200612-08 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - - -

ERRATA: [ GLSA 200612-03 ] GnuPG: Multiple vulnerabilities

2006-12-11 Thread Raphael Marichez
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory [ERRATA UPDATE]GLSA 200612-03:02 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - - -

Firefox 2.0 security bug: Extensions can hide themself

2006-12-11 Thread azurIt
Background -- Firefox is very popular and secure web browser. Until now, it is used by millions of people and thousands of internet clubs. One of the great features of Firefox are extensions. You can use them to create things inside your browser which are beyond your imagination. Overview

RFIDIOt release - version 0.1i

2006-12-11 Thread Adam Laurie
I'm pleased to announce a new release of RFIDIOt, the open source python RFID library. New in this version: Read/Write Decode/Encode FDX-B (EM4x05 - ISO11784/5 'animal') tags (to Q5 or Hitag2) Read/Write Decode/Encode EM4x02 'Unique' tags (to Q5) Updated GUI for e-passports Full deta

[ MDKSA-2006:226 ] - Updated squirrelmail packages fix vulnerabilities

2006-12-11 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDKSA-2006:226 http://www.mandriva.com/security/ ___

WASC-Announcement: MX Injection - Capturing and Exploiting Hidden Mail Servers By Vicente Aguilera Diaz

2006-12-11 Thread robert
The Web Application Security Consortium is proud to present 'MX Injection: Capturing and Exploiting Hidden Mail Servers' written by Vicente Aguilera Diaz of Internet Security Auditors. In this article Vicente discusses how an attacker can inject additional commands into an online web mail appl

D-LINK DWL-2000AP+ remote DoS

2006-12-11 Thread poplix
D-LINK DWL-2000AP+ with firmware version 2.11 is prone to two remote denial of service vulnerability because it fails to handle arp flooding. The first vuln causes the wireless link (802.11) to be resetted and the arp table to be rebuilded. All clients connected to the AP are disconnected. This

Unauthenticated access to IBM Host On-Demand administration pages

2006-12-11 Thread Ferguson, David (Kansas City)
SUMMARY Vulnerability found in: IBM WebSphere Host On-Demand (HOD) Type: Unauthorized, remote access to HOD administration pages Applies to: Version 6.0, 7.0, 8.0, and 9.0 (possibly 10.0) Severity Level: High Exploit Difficulty: Very Low Initial Vendor Notification: approximately 11/3/2006 Discove

[SBDA] - ColdFusion MX7 - Multiple Vulnerabilities

2006-12-11 Thread Brett Moore
Just clearing stuff out before Christmas. = ColdFusion MX7 - Multiple Vulnerabilities = = Vendor Website: = http://www.Adobe.com = = Affected Software: = ColdFusion MX7 (and possibly MX6) = = Public disclosure on Mond

[ GLSA 200612-09 ] MadWifi: Kernel driver buffer overflow

2006-12-11 Thread Raphael Marichez
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200612-09 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - - -

[SECURITY] [DSA 1233-1] New Linux 2.6.8 packages fix several vulnerabilities

2006-12-11 Thread Dann Frazier
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1233-1[EMAIL PROTECTED] http://www.debian.org/security/ Dann Frazier December 10th, 2006

[ GLSA 200612-04 ] ModPlug: Multiple buffer overflows

2006-12-11 Thread Raphael Marichez
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200612-04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - - -