[SECURITY] [DSA-1970-1] New openssl packages fix denial of service

2010-01-13 Thread Stefan Fritsch
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - Debian Security Advisory DSA-1970-1 secur...@debian.org http://www.debian.org/security/ Stefan Fritsch January 13, 2010

[security bulletin] HPSBPI02500 SSRT090263 rev.1 - HP Web Jetadmin, Remote Unauthorized Access to Data, Denial of Service (DoS)

2010-01-13 Thread security-alert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c01975278 Version: 1 HPSBPI02500 SSRT090263 rev.1 - HP Web Jetadmin, Remote Unauthorized Access to Data, Denial of Service (DoS) NOTICE: The information in this Security Bulletin should be acte

[ MDVSA-2010:004 ] bash

2010-01-13 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2010:004 http://www.mandriva.com/security/

[CORE-2009-1209] Google SketchUp 'lib3ds' 3DS Importer Memory Corruption

2010-01-13 Thread CORE Security Advisories
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Core Security Technologies - CoreLabs Advisory http://www.coresecurity.com/corelabs/ Google SketchUp 'lib3ds' 3DS Importer Memory Corruption 1. *Advisory Information* Title: Google SketchUp 'lib3ds' 3DS Importer Memory Corruption

Yoono Firefox Extension - Privileged Code Injection

2010-01-13 Thread Nick Freeman
(, ) (, . `.' ) ('.', ). , ('. ( ) ( (_,) .`), ) _ _, / _/ / _ \ _ \ \==/ /_\ \ _/ ___\/ _ \ / \ / \/ |\\ \__( <_> ) Y Y \ /__ /\___|__ / \___ >/|__|_| / \/ \/.-.\/ \/:wq

[USN-883-1] network-manager-applet vulnerabilities

2010-01-13 Thread Marc Deslauriers
=== Ubuntu Security Notice USN-883-1 January 13, 2010 network-manager-applet vulnerabilities CVE-2009-4144, CVE-2009-4145 === A security issue affects the following Ubuntu rele

[USN-881-1] Kerberos vulnerability

2010-01-13 Thread Kees Cook
=== Ubuntu Security Notice USN-881-1 January 12, 2010 krb5 vulnerability CVE-2009-4212 === A security issue affects the following Ubuntu releases: Ubuntu 6.06 LTS Ubuntu 8.04

[SECURITY] [DSA-1969-1] New krb5 packages fix denial of service

2010-01-13 Thread Giuseppe Iuculano
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - Debian Security Advisory DSA-1969-1 secur...@debian.org http://www.debian.org/security/Giuseppe Iuculano January 12, 2010

[ MDVSA-2010:003 ] sendmail

2010-01-13 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2010:003 http://www.mandriva.com/security/

iDefense Security Advisory 01.12.10: Adobe Reader and Acrobat JpxDecode Memory Corruption Vulnerability

2010-01-13 Thread iDefense Labs
iDefense Security Advisory 01.12.10 http://labs.idefense.com/intelligence/vulnerabilities/ Jan 12, 2010 I. BACKGROUND Adobe Reader and Acrobat are Portable Document Format (PDF) reader and processors. For more information, please visit following pages: http://www.adobe.com/products/reader/ http:

Cross Site Identification (CSID) attack. Description and demonstration.

2010-01-13 Thread Ronen Z
Hi, A new type of vulnerability is described in which publicly available information from social network sites obtained out of context, can be used to identify a user in cases where anonymity is taken for granted. This attack (dubbed Cross Site Identification, or CSID) assumes the following scena

MITKRB5-SA-2009-004 [CVE-2009-4212] integer underflow in AES and RC4 decryption

2010-01-13 Thread Tom Yu
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 MITKRB5-SA-2009-004 MIT krb5 Security Advisory 2009-004 Original release: 2010-01-12 Topic: integer underflow in AES and RC4 decryption CVE-2009-4212 integer underflow in AES and RC4 decryption CVSSv2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:POC/RL:OF/

[CORELAN-10-004] TurboFTP Server 1.00.712 remote DoS

2010-01-13 Thread Security
|--| | __ __ | | _ / /___ _ / / _ ___ | | / ___/ __ \/ ___/ _ \/ / __ `/ __ \ / __/ _ \/ __ `/ __ `__ \ | | / /__/ /_/ / / / __

ZDI-10-002: Oracle Secure Backup observiced.exe Remote Code Execution Vulnerability

2010-01-13 Thread ZDI Disclosures
ZDI-10-002: Oracle Secure Backup observiced.exe Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-002 January 12, 2010 -- CVE ID: CVE-2010-0072 -- Affected Vendors: Oracle -- Affected Products: Oracle Secure Backup -- Vulnerability Details: This vulnerabili

Secunia Research: Microsoft Windows Flash Player Movie Unloading Vulnerability

2010-01-13 Thread Secunia Research
== Secunia Research 12/01/2010 - Microsoft Windows Flash Player Movie Unloading Vulnerability - == Table of Contents Affected Softwar