[USN-616-1] X.org vulnerabilities

2008-06-13 Thread Kees Cook
=== Ubuntu Security Notice USN-616-1 June 13, 2008 xorg-server vulnerabilities CVE-2008-1377, CVE-2008-1379, CVE-2008-2360, CVE-2008-2361, CVE-2008-2362 === A security issu

AS/400 Vulnerabilities

2008-06-13 Thread Jon Kibler
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi, Have you ever nmap-ed a network with AS/400s? If you have, you probably know that doing so will, in at least half the cases, either crash the box, hang up one or more services, or really confuse the IP stack to the point that the box almost screec

Exploit for vBulletin "obscure" XSS (3.7.1 & 3.6.10)

2008-06-13 Thread Jessica Hope
== Advisory : Exploit for vBulletin "obscure" XSS Release Date : June 13th 2008 Application : vBulletin Version : vBulletin 3.7.1 and lower, vBulletin 3.6.10 and lower Platform : PHP Vendor URL : http://www.vbulletin.com/ Authors

[USN-612-10] OpenVPN regression

2008-06-13 Thread Jamie Strandboge
=== Ubuntu Security Notice USN-612-10 June 12, 2008 openvpn regression https://launchpad.net/bugs/230197 === A security issue affects the following Ubuntu releases: Ubuntu

Securify bulletin: Microsoft Active Directory Denial-of-service

2008-06-13 Thread Securify Bulletins
SECURIFY Bulletin: Active Directory Denial-of-service = I. SUMMARY: SECURIFY has discovered a denial-of-service vulnerability in Microsoft Active Directory (AD) in which a domain user sending a specially-crafted LDAP request causes the Active

[USN-612-9] openssl-blacklist update

2008-06-13 Thread Jamie Strandboge
=== Ubuntu Security Notice USN-612-9 June 12, 2008 openssl-blacklist update http://www.ubuntu.com/usn/usn-612-1 http://www.ubuntu.com/usn/usn-612-3 http://www.ubuntu.com/usn/usn-612-8 =

RE: AS/400 Vulnerabilities

2008-06-13 Thread Michael Wojcik
> From: Jon Kibler [mailto:[EMAIL PROTECTED] > Sent: Thursday, 12 June, 2008 14:54 > To: bugtraq@securityfocus.com > > 2) Are the boxes really just unstable to malformed network > data, but not exploitable? Exploiting data-handling vulnerabilities (as opposed to design vulnerabilities, like m

RE: Securify bulletin: Microsoft Active Directory Denial-of-service

2008-06-13 Thread Michael Wojcik
> From: Securify Bulletins [mailto:[EMAIL PROTECTED] > Sent: Friday, 13 June, 2008 12:44 > To: bugtraq@securityfocus.com; [EMAIL PROTECTED] > > IV. WORKAROUNDS: > > Block TCP ports 389 and 3268 to your Active Directory > server from untrusted sources. AD may also be listening on 636 for LDAP-