Troopers08 Security Conference, April 23/24 (Munich/Germany)

2008-04-15 Thread Enno Rey
Troopers08 Presentations Keynote on Invulnerable Software - Dan Bernstein KIDS - Kernel Intrusion Detection System - Rodrigo Branco State of Security - Andrew Cushman, Microsoft Release of the next revision of the free Exploit-Me series of application penetration

[ GLSA 200804-15 ] libpng: Execution of arbitrary code

2008-04-15 Thread Robert Buchholz
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200804-15 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - -

[ GLSA 200804-14 ] Opera: Multiple vulnerabilities

2008-04-15 Thread Robert Buchholz
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200804-14 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - -

[ GLSA 200804-13 ] Asterisk: Multiple vulnerabilities

2008-04-15 Thread Robert Buchholz
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200804-13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - -

Dotclear 'ecrire/images.php' Arbitrary File Upload Vulnerability

2008-04-15 Thread Morgan ARMAND
# Advisory #1 Dotclear 'ecrire/images.php' Arbitrary File Upload Vulnerability $ Author : Morgan ARMAND $ Contact : armand_m at epitech dot net $ Vendor URL : http://www.dotclear.net $ Vendor Contacted : 07/04/2008 $ Vendor

BosNews v4.0 Remote add user admin

2008-04-15 Thread houssamix
-- - H-T Team [ HouSSaMix + ToXiC350 ] from MoroCCo -

clamav: Endless loop / hang with crafter arj, CVE-2008-1387

2008-04-15 Thread Hanno Böck
Advisory published at: http://int21.de/cve/CVE-2008-1387-clamav.html clamav: Endless loop / hang with crafter arj, CVE-2008-1387 References http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1387 http://svn.clamav.net/svn/clamav-devel/trunk/ChangeLog

BosNews 2002-2006 Remote add user admin

2008-04-15 Thread houssamix
-- - H-T Team [ HouSSaMix + ToXiC350 ] from MoroCCo -

Re: Secunia Research: Lotus Notes Folio Flat File Parsing Buffer Overflows

2008-04-15 Thread Luigi Auriemma
Autonomy Keyview Folio Flat File Parsing Buffer Overflows Autonomy Keyview Applix Graphics Parsing Vulnerabilities Autonomy Keyview EML Reader Buffer Overflows activePDF DocConverter Folio Flat File Parsing Buffer Overflows activePDF DocConverter Applix Graphics Parsing Vulnerabilities

[ MDVSA-2008:086 ] - Updated kernel packages fix vulnerability

2008-04-15 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2008:086 http://www.mandriva.com/security/

[SECURITY] [DSA 1540-2] New lighttpd packages fix denial of service

2008-04-15 Thread Steve Kemp
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - Debian Security Advisory DSA-1540-2 [EMAIL PROTECTED] http://www.debian.org/security/ Steve Kemp April 15, 2008

Koobi CMS 4.2.4/4.2.5/4.3.0 Multiple Remote SQL Injection Vulnerabilities

2008-04-15 Thread sys-project
--==+=== Spanish Hackers Team (www.spanish-hackers.com) =+==-- --==+ Koobi CMS 4.3.0, 4.2.5, 4.2.4 Multiple Remote SQL Injection +==-- --==++==--

WordPress 2.5 - Salt cracking vulnerability

2008-04-15 Thread J. Carlos Nieto
WORDPRESS 2.5 - SALT CRACKING VULNERABILITY --- http://xiam.menteslibres.org/pages/advisories/wordpress-2-5-salt-cracking-vulnerability By J. Carlos Nieto [EMAIL PROTECTED] http://xiam.menteslibres.org Severity Medium. It affects

Koobi Pro 6.25 poll Remote SQL Injection Vulnerability

2008-04-15 Thread Sabun
## # # Koobi Pro 6.25 poll Remote SQL Injection Vulnerability # ## # ##AUTHOR : [EMAIL PROTECTED] # HOME : http://www.r57shell.in ##WEBSiTE: http://www.xcorpitx-hack.com/Forum/ BLOG :

remote file include

2008-04-15 Thread win32 . exe
# W2B Online Banking Remote File Inclusion Vulnerability # ## AUTHOR: THuM4N ## Email : [EMAIL PROTECTED] ## Script : W2B Online Banking

iDefense Security Advisory 04.14.08: ClamAV libclamav PE WWPack Heap Overflow Vulnerability

2008-04-15 Thread iDefense Labs
iDefense Security Advisory 04.14.08 http://labs.idefense.com/intelligence/vulnerabilities/ Apr 14, 2008 I. BACKGROUND Clam AntiVirus is a multi-platform GPL anti-virus toolkit. ClamAV is often integrated into e-mail gateways and used to scan e-mail traffic for viruses. It supports virus

remote file include

2008-04-15 Thread win32 . exe
# Istant-Replay Forum Remote File Inclusion Vulnerability # ## AUTHOR: THuGM4N ## Email : [EMAIL PROTECTED] ## Script : Istant-Replay

DIVX Player = 6.7.0 Buffer Overflow PoC ( .SRT )

2008-04-15 Thread securfrog
# DIVX Player = 6.7.0 Buffer Overflow PoC ( .SRT ) # Bug: When parsing a subtitle file with an overly long subtitle DIVX player will deadly crash with eip overwritted # Replace MOVIE_FILENAME by your movie filename ( .avi ) # #!/usr/local/bin/perl

[ MDVSA-2008:086 ] - Updated kernel packages fix vulnerability

2008-04-15 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2008:086 http://www.mandriva.com/security/