[SECURITY] [DSA 1324-1] New hiki packages fix missing input sanitising

2007-06-29 Thread Steve Kemp
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - Debian Security Advisory DSA-1324[EMAIL PROTECTED] http://www.debian.org/security/ Steve Kemp June 28, 2007 -

Re: eTicket version 1.5.5 XSS Attack Vulnerability

2007-06-29 Thread sf
The severity of this bug is inaccurate. Considering this bug is simply XSS, and only available when register_globals is On I would consider this "Very Low". Ultimately eTicket is not designed to work with register_globals On, please turn it off. It is set to off in php.ini by default.

flac123 0.0.9 - Stack overflow in comment parsing

2007-06-29 Thread David Thiel
iSEC Partners Security Advisory - 2007-002-flactools http://www.isecpartners.com flac123 0.0.9 - Stack overflow in comment parsing Vendor URL: http://flac-tools.sourceforge.net/ Severity: High (Allows for arbitrary code execution) Author: David Thiel

SQL Injection In Script VBZooM V1.12

2007-06-29 Thread RaeD
Discovered By: Hasadya Raed Contact : [EMAIL PROTECTED] Israel --- Script : VBZooM V1.12 VBZooM V1.12 "reply.php" SQL Injection Dork : POWERED BY VBZooM V1.12 --- B.File : reply.php --- Exploit : http://www.victim.com/Path_Scr

Airscanner Advisory #07062901: FlexiSPY Victim/User Database Exposure (Full world readable access to ALL SMS/Emails/Voice data from victims/users)

2007-06-29 Thread Airscanner Corp.
http://airscanner.com/security/07062901_flexispy.htm Airscanner Mobile Security Advisory #07062901: FlexiSPY Victim/User Database Exposure (Full world readable access to ALL SMS/Emails/Voice data from victims/users) Product: FlexiSpy.com Website Platform: NA Requirements: NA Credits: Seth Fo

[SECURITY] [DSA 1325-1] New evolution packages fix arbitrary code execution

2007-06-29 Thread Moritz Muehlenhoff
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1325-1[EMAIL PROTECTED] http://www.debian.org/security/ Moritz Muehlenhoff June 29th, 2007

TSLSA-2007-0021 - kerberos5

2007-06-29 Thread Trustix Security Advisor
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Trustix Secure Linux Security Advisory #2007-0021 Package names: kerberos5 Summary: Multiple vulnerabilities Date: 2007-06-29 Affected versions: Tr

[USN-479-1] MadWifi vulnerabilities

2007-06-29 Thread Kees Cook
=== Ubuntu Security Notice USN-479-1 June 28, 2007 linux-restricted-modules-2.6.15/.17/.20 vulnerabilities CVE-2006-7177, CVE-2006-7178, CVE-2006-7179, CVE-2006-7180, CVE-2007-2829, CVE-2007-2830, CVE-2007-2831 ==