[SECURITY] [DSA 1816-1] New apache2 packages fix privilege escalation

2009-06-16 Thread Stefan Fritsch
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - Debian Security Advisory DSA-1816-1 secur...@debian.org http://www.debian.org/security/ Stefan Fritsch June 16, 2009

ZDI-09-043: Apple Java CColorUIResource Pointer Derference Code Execution Vulnerability

2009-06-16 Thread ZDI Disclosures
ZDI-09-043: Apple Java CColorUIResource Pointer Derference Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-09-043 June 16, 2009 -- CVE ID: CVE-2009-1719 -- Affected Vendors: Apple -- Affected Products: Apple Java -- TippingPoint(TM) IPS Customer Protection: Tipping

Re: [Full-disclosure] WinAppDbg version 1.2 is out!

2009-06-16 Thread Mario Alejandro Vilas Jerez
Basically it's got some different features than PyDbg and a more complete documentation. If you have an *existing* project built upon PyDbg it's probably not worth switching (unless you've hit some very bad problem with it) but I believe it's better for newer projects, as this new library is more f

Re: [Full-disclosure] WinAppDbg version 1.2 is out!

2009-06-16 Thread Jared DeMott
Mario Alejandro Vilas Jerez wrote: > What is WinAppDbg? > == > > The WinAppDbg python module allows developers to quickly code instrumentation > scripts in Python under a Windows environment. Can you compare/contrast with pydbg so I can understand why I might want to give it a try

WinAppDbg version 1.2 is out!

2009-06-16 Thread Mario Alejandro Vilas Jerez
What is WinAppDbg? == The WinAppDbg python module allows developers to quickly code instrumentation scripts in Python under a Windows environment. It uses ctypes to wrap many Win32 API calls related to debugging, and provides an object-oriented abstraction layer to manipulate thre

phpMyTourney adminfunctions.php Remote File Include Vulnerabilities

2009-06-16 Thread IrIsT . Ir
Hi a bug in phpMyTourney that allows to us to occur a Remote File Include on a Remote machin. Bug : # # # #

[ MDVSA-2009:133 ] irssi

2009-06-16 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2009:133 http://www.mandriva.com/security/

Official release of "Keykeriki" open source wireless keyboard sniffer

2009-06-16 Thread Max Moser
Hi everyone, i just like to announce officially the release of our wireless keyboard sniffer Keykeriki. An addition to the official press release; Website: http://www.remote-exploit.org/Keykeriki.html Video with some demonstration available on website as well Contact: hardh...@remote-exploit.org

CA20090615-02: CA Service Desk Tomcat Cross Site Scripting Vulnerability

2009-06-16 Thread Williams, James K
Title: CA20090615-02: CA Service Desk Tomcat Cross Site Scripting Vulnerability CA Advisory Reference: CA20090615-02 CA Advisory Date: 2009-06-15 Impact: A remote attacker can inject arbitrary web script or HTML. Summary: The release of Tomcat as included with CA Service Desk r11.2 is po

CA20090615-01: CA ARCserve Backup Message Engine Denial of Service Vulnerabilities (Updated)

2009-06-16 Thread Williams, James K
Title: CA20090615-01: CA ARCserve Backup Message Engine Denial of Service Vulnerabilities CA Advisory Reference: CA20090615-01 CA Advisory Date: 2009-06-15 Reported By: iViZ Security Research Team Impact: A remote attacker can cause a denial of service. Summary: CA ARCserve Backup conta

CA20090615-01: CA ARCserve Backup Message Engine Denial of Service Vulnerabilities

2009-06-16 Thread Williams, James K
Title: CA20090615-01: CA ARCserve Backup Message Engine Denial of Service Vulnerabilities CA Advisory Reference: CA20090615-01 CA Advisory Date: 2009-06-15 Reported By: iViZ Security Research Team Impact: A remote attacker can cause a denial of service. Summary: CA ARCserve Backup conta

[TZO-40-2009] Clamav generic bypass (RAR,CAB,ZIP)

2009-06-16 Thread Thierry Zoller
From the low-hanging-fruit-department Clamav generic evasion (RAR,CAB,ZIP) Shameless plug :

Re[2]: [Full-disclosure] Netgear DG632 Router Remote DoS Vulnerability

2009-06-16 Thread Vladimir '3APA3A' Dubrovin
Dear Tom Neaves, It still can be exploited from Internet even if "remote management" is only accessible from local network. If you can trick user to visit Web page, you can place a form on this page which targets to router and request to router is issued from victim's browser. --Tuesday

[TZO-33-2009] Fprot generic bypass (TAR)

2009-06-16 Thread Thierry Zoller
From the low-hanging-fruit-department F-prot generic TAR bypass / evasion Shameless plug : ---

Re: [Full-disclosure] Netgear DG632 Router Remote DoS Vulnerability

2009-06-16 Thread Hanno Böck
Am Montag 15 Juni 2009 schrieb Tom Neaves: > Within the "/cgi-bin/" directory of the administrative web interface exists > a > file called "firmwarecfg". This file is used for firmware upgrades. A > HTTP POST > request for this file causes the web server to hang. The web server will > stop > res

Re: VUPEN Security - Microsoft Office Word Document Parsing Buffer Overflow Vulnerability

2009-06-16 Thread Nick Boyce
On Thu, Jun 11, 2009 at 10:14 PM, VUPEN Security Research wrote: > III. AFFECTED PRODUCTS > > > According to the vendor, the following products are affected: > > - Microsoft Office Word 2007 Service Pack 2 > - Microsoft Office Word 2007 Service Pack 1 > - Microsoft

Re: Netgear DG632 Router Remote DoS Vulnerability

2009-06-16 Thread Tom Neaves
Hi. I see where you're going but I think you're missing the point a little. By *default* the web interface is enabled on the LAN and accessible by anyone on that LAN and the "remote management" interface (for the Internet) is turned off. If the "remote management" interface was enabled, stop