[SECURITY] [DSA 1805-1] New pidgin packages fix several vulnerabilities

2009-05-22 Thread Moritz Muehlenhoff
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - Debian Security Advisory DSA-1805-1 secur...@debian.org http://www.debian.org/security/ Moritz Muehlenhoff May 22, 2009

[TZO-25-2009] Panda generic evasion (TAR)

2009-05-22 Thread Thierry Zoller
From the low-hanging-fruit-department Panda generic evasion (TAR) Why are there two panda advisories instead of one ?

[TZO-24-2009] Panda generic evasion (CAB)

2009-05-22 Thread Thierry Zoller
From the low-hanging-fruit-department Panda generic evasion (CAB) Why are there two panda advisories instead of one ?

LxBlog

2009-05-22 Thread info
# Securitylab.ir # Application Info: # Name: LxBlog # Website: http://www.lxblog.net # # Discoverd By: Securitylab.ir # Website: http://securitylab.ir # Contacts: admin[at]securit

Serena Dimensions CM Desktop Client does not validate the server SSL certificate

2009-05-22 Thread roland . gruber . extern
Application: Serena Dimensions CM Affected versions: 10.1 and later Vulnerability: man-in-the-middle attacks Problem type: remote Problem description: The client/server connection can be SSL encrypted by setting "-ssl" in the listener.dat. The problem is that the Desktop cli

[SECURITY] [DSA 1802-2] New squirrelmail packages correct incomplete fix

2009-05-22 Thread Thijs Kinkhorst
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - Debian Security Advisory DSA-1802-2 secur...@debian.org http://www.debian.org/security/ Thijs Kinkhorst May 21, 2009

[ MDVSA-2009:121 ] lcms

2009-05-22 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2009:121 http://www.mandriva.com/security/

Novell GroupWise Internet Agent Remote Buffer Overflow Vulnerabilities

2009-05-22 Thread VUPEN Security Research
VUPEN Security Research Advisory - VUPEN-SR-2009-01 // VUPEN-SR-2009-02 Advisory URL: http://www.vupen.com/english/advisories/2009/1393 May 22, 2009 I. BACKGROUND -- Novell GroupWise is a complete collaboration software solution that provides information workers with e-ma

DotNetNuke ErrorPage.aspx Cross-Site Scripting Vulnerability

2009-05-22 Thread Ben Hawkes
--- Lateral Security Advisory 20090430-001 --- Name: DotNetNuke ErrorPage.aspx Cross-Site Scripting Vulnerability Reported: 30th April 2009 Published: 22nd May 2009 Background: DotNetNuke is one of the most widely adopted open source framework for website content management and web application dev