[USN-922-1] libnss-db vulnerability

2010-04-01 Thread Kees Cook
=== Ubuntu Security Notice USN-922-1 March 31, 2010 libnss-db vulnerability CVE-2010-0826 === A security issue affects the following Ubuntu releases: Ubuntu 8.04 LTS Ubuntu

VUPEN Security Research - Apple iTunes ColorSync Profile Integer Overflow Vulnerability

2010-04-01 Thread VUPEN Security Research
VUPEN Security Research - Apple iTunes ColorSync Profile Integer Overflow Vulnerability http://www.vupen.com/english/research.php I. BACKGROUND - "iTunes is a free application for Mac or PC. It organizes and plays digital music and video on computers. It syncs all media fi

VUPEN Security Research - Apple Quicktime PICT Processing Integer Overflow Vulnerability

2010-04-01 Thread VUPEN Security Research
VUPEN Security Research - Apple Quicktime PICT Processing Integer Overflow Vulnerability http://www.vupen.com/english/research.php I. BACKGROUND - "Apple QuickTime is software that allows Mac and Windows users to play back audio and video on their computers. But taking a d

VUPEN Security Research - Sun Java JDK/JRE Unpack200 Buffer Overflow Vulnerability

2010-04-01 Thread VUPEN Security Research
VUPEN Security Research - Sun Java JDK/JRE Unpack200 Buffer Overflow Vulnerability http://www.vupen.com/english/research.php I. BACKGROUND - "Java is a programming language and computing platform released by Sun Microsystems. It is the underlying technology that powers sta

CSRF Vulnerability in OSSIM 2.2.1

2010-04-01 Thread nicolas . grandjean
== Summary == CSRF Vulnerability in OSSIM 2.2.1 Discovered by: CONIX Security (www.conix.fr) Public Release Date: 4/01/2010 Vendor: Alienvault (www.alienvault.com) = Technical Details = The page /ossim/control_panel/alarm_console.php is vu

DynPG CMS v4.1.0 Multiple Remote File Inclusion Vulnerability

2010-04-01 Thread eidelweiss
Dear, I found Some vulnerability in DynPG CMS , This the full exploit code: [+]Title: DynPG CMS Multiple Remote File Inclusion Vulnerability [+]Version: 4.1.0 (Other or lower versions may also be affected) [+]Download:http://www.dynpg.org/download_en.php [+]License: GNU

VUPEN Security Research - Apple Quicktime FLC Encoded Movie Heap Overflow Vulnerability

2010-04-01 Thread VUPEN Security Research
VUPEN Security Research - Apple Quicktime FLC Encoded Movie Heap Overflow Vulnerability http://www.vupen.com/english/research.php I. BACKGROUND - "Apple QuickTime is software that allows Mac and Windows users to play back audio and video on their computers. But taking a dee

VUPEN Security Research - Sun Java JDK/JRE AWT Library Invalid Pointer Vulnerability

2010-04-01 Thread VUPEN Security Research
VUPEN Security Research - Sun Java JDK/JRE AWT Library Invalid Pointer Vulnerability http://www.vupen.com/english/research.php I. BACKGROUND - "Java is a programming language and computing platform released by Sun Microsystems. It is the underlying technology that powers s

Zabbix <= 1.8.1 SQL Injection

2010-04-01 Thread Dawid Golunski
= - Release date: April 1st, 2010 - Discovered by: Dawid Golunski - Severity: High = I. VULNERABILITY - Zabbix <= 1.8.1 SQL Injection II. BACKGROUND - Zabbix is

VUPEN Security Research - Sun Java JDK/JRE AWT Library Invalid Index Vulnerability

2010-04-01 Thread VUPEN Security Research
VUPEN Security Research - Sun Java JDK/JRE AWT Library Invalid Index Vulnerability http://www.vupen.com/english/research.php I. BACKGROUND - "Java is a programming language and computing platform released by Sun Microsystems. It is the underlying technology that powers sta

Juniper SRX Critical Denial of Service Vulnerability

2010-04-01 Thread J. Oquendo
*Juniper SRX Critical Denial of Service Vulnerability* *Overview* According to Google Finance: /Juniper Networks, Inc. designs, develops and sells products and services that together provide its customers with network infrastructure that creates responsive and trusted environments for accelerati

VUPEN Security Research - Apple Quicktime PICT Handling Heap Overflow Vulnerability

2010-04-01 Thread VUPEN Security Research
VUPEN Security Research - Apple Quicktime PICT Handling Heap Overflow Vulnerability http://www.vupen.com/english/research.php I. BACKGROUND - "Apple QuickTime is software that allows Mac and Windows users to play back audio and video on their computers. But taking a deeper

VMSA-2010-0006 ESX Service Console updates for samba and acpid

2010-04-01 Thread VMware Security Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - VMware Security Advisory Advisory ID: VMSA-2010-0006 Synopsis: ESX Service Console updates for samba and acpid Issue date:2010-04-01 U