Low severity flaw in various applications including KSSL, Rekonq, Arora, Psi IM

2011-10-07 Thread Tim Brown
I recently discovered that various Qt applications including KSSL (the KDE class library responsible for SSL negotiation), Rekonq, Arora and Psi IM are vulnerable to UI spoofing due to their use of QLabel objects to render externally controlled security critical information. The primary area of

Medium severity flaw with Ark

2011-10-07 Thread Tim Brown
I recently discovered that the Ark archiving tool is vulnerable to directory traversal via malformed. When attempts are made to view files within the malformed Zip file in Ark's default view, the wrong file may be displayed due to incorrect construction of the temporary file name. Whilst this

VUPEN Security Research - Google Chrome WebKit Engine Child Tag Deletion Stale Pointer Vulnerability

2011-10-07 Thread VUPEN Security Research
VUPEN Security Research - Google Chrome WebKit Engine Child Tag Deletion Stale Pointer Vulnerability Website : http://www.vupen.com/english/research.php Twitter : http://twitter.com/vupen I. BACKGROUND - "Google Chrome is a web browser developed by Google that uses the We

VUPEN Security Research - Google Chrome WebKit Engine Ruby Tag Stale Pointer Vulnerability

2011-10-07 Thread VUPEN Security Research
VUPEN Security Research - Google Chrome WebKit Engine Ruby Tag Stale Pointer Vulnerability Website : http://www.vupen.com/english/research.php Twitter : http://twitter.com/vupen I. BACKGROUND - "Google Chrome is a web browser developed by Google that uses the WebKit layou

Secunia Research: Autonomy Keyview Ichitaro Object Reconstruction Logic Vulnerability

2011-10-07 Thread Secunia Research
== Secunia Research 07/10/2011 - Autonomy Keyview - - Ichitaro Object Reconstruction Logic Vulnerability - ==

Secunia Research: Autonomy Keyview Ichitaro Text Parsing Buffer Overflow

2011-10-07 Thread Secunia Research
== Secunia Research 07/10/2011 - Autonomy Keyview Ichitaro Text Parsing Buffer Overflow - == Table of Contents Affected Software..

Secunia Research: Autonomy Keyview Ichitaro QLST Integer Overflow Vulnerability

2011-10-07 Thread Secunia Research
== Secunia Research 07/10/2011 - Autonomy Keyview Ichitaro QLST Integer Overflow Vulnerability - == Table of Contents Affected Softwar

[SECURITY] [DSA 2318-1] cyrus-imapd-2.2 security update

2011-10-07 Thread Nico Golde
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA-2318-1secur...@debian.org http://www.debian.org/security/ Nico Golde Oct 6, 2011