CA20130213-01: Security Notice for CA ControlMinder

2013-02-14 Thread Kotas, Kevin J
-BEGIN PGP SIGNED MESSAGE- CA20130213-01: Security Notice for CA ControlMinder Issued: February 13, 2013 CA Technologies Support is alerting customers to a potential risk with CA ControlMinder. A vulnerability exists that can allow a remote attacker to execute arbitrary code. CA has issu

Sonicwall OEM Scrutinizer v9.5.2 - Multiple Vulnerabilities

2013-02-14 Thread Vulnerability Lab
Title: == Sonicwall OEM Scrutinizer v9.5.2 - Multiple Vulnerabilities Date: = 2013-02-14 References: === http://www.vulnerability-lab.com/get_content.php?id=786 VL-ID: = 786 Common Vulnerability Scoring System: 5.2 Introduction: ===

Sonicwall Scrutinizer v9.5.2 - SQL Injection Vulnerability

2013-02-14 Thread Vulnerability Lab
Title: == Sonicwall Scrutinizer v9.5.2 - SQL Injection Vulnerability Date: = 2013-02-13 References: === http://www.vulnerability-lab.com/get_content.php?id=789 #9984: Investigate Vulnerability Lab issues (this ticket included tracking the creation of our DBI shim to error on s

[slackware-security] pidgin (SSA:2013-044-01)

2013-02-14 Thread Slackware Security Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 [slackware-security] pidgin (SSA:2013-044-01) New pidgin packages are available for Slackware 12.2, 13.0, 13.1, 13.37, 14.0, and -current to fix security issues. Here are the details from the Slackware 14.0 ChangeLog: +--+

Re: Aastra IP Telephone encrypted .tuz configuration file leakage

2013-02-14 Thread noreply
Vulnerability fixed in August 2012 release of anacrypt V1.04 encryption tool. Available on the www.aastra.com website. IP Phone Configuration File Encryption Tool - Microsoft Windows (Version 1.04, 08/2012, gz) (English, 45.78 KB) IP Phone Configuration File Encryption Tool - Linux 32 bit (Ve

[security bulletin] HPSBMU02815 SSRT100715 rev.5 - HP SiteScope SOAP Security Issues, Remote Disclosure of Information, Remote Code Execution

2013-02-14 Thread security-alert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Note: the current version of the following document is available here: https://h20566.www2.hp.com/portal/site/hpsc/public/kb/ docDisplay?docId=emr_na-c03489683 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c03489683 Version: 5 HPSBMU02815 S

Multiple Vulnerabilities in Edimax EW-7206-APg and EW-7209APg

2013-02-14 Thread devnull
Device Name: EW-7206APg / EW-7209APg Vendor: Edimax Vulnerable Firmware Releases: Device: EW-7206APg Hardware Version Rev. A Runtime Code Version v1.32 Runtime Code Version V1.33 Device: EW-7209APg Hardware Version Rev. A Runtime

[SECURITY] [DSA 2623-1] openconnect security update

2013-02-14 Thread Florian Weimer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - Debian Security Advisory DSA-2623-1 secur...@debian.org http://www.debian.org/security/Florian Weimer February 14, 2013

[IA46] Photodex ProShow Producer v5.0.3297 ColorPickerProc() Memory Corruption

2013-02-14 Thread Inshell Security
Inshell Security Advisory http://www.inshell.net 1. ADVISORY INFORMATION --- Product:Photodex ProShow Producer Vendor URL: www.photodex.com Type: Improper Restriction of Operations within the Bounds of a Memory Buffer[CWE-119] Date found: